System and method for secure end-to-end electronic communication using variation table of entropy
Through a private shared entropy table and predefined hash algorithm, and a dynamic deformation entropy table, the problem of knowing the seed value of the pseudo-random number generator is solved, and efficient and secure information transmission between devices and anti-reverse engineering of encryption keys is realized.
Patent Information
- Application Number
- CN202380079642.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-16
- Filing Date
- 2023-11-15
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, when the seed value of the pseudo-random number generator is known, it leads to damage to the security system, making it difficult to efficiently and securely transmit information between devices.
Using a private shared entropy table, dynamic deformation entropy table is generated and transmitted through predefined hashing algorithms and deformation protocols, ensuring that each user device can decrypt data synchronously.
It improves the security and privacy of information transmission, prevents reverse engineering of encryption keys, adapts to dynamic changes of equipment, and enhances the security and synchronization performance of the system.
Smart Images

Figure CN120283377A_ABST
Abstract
Description
[0001] Priority and Related Applications
[0002] This application is a continuation of U.S. Patent Application Serial No. 17 / 988,710, titled "System and Method for Secure End-To-End Electronic Communication Using a Mutating Table of Entropy", filed on November 16, 2022. U.S. Patent Application Serial No. 17 / 988,710 is a partial continuation of U.S. Patent Application Serial No. 17 / 385,817, titled "System and Method for Secure End-To-End Electronic Communication Using a Privately Shared Table of Entropy", filed on July 26, 2021. U.S. Patent Application Serial No. 17 / 385,817 is a continuation of U.S. Patent Application Serial No. 17 / 382,282, titled "System and Method for Secure End-To-End Electronic Communication Using a Privately Shared Table of Entropy", filed on July 21, 2021, which claims the priority of U.S. Provisional Patent Application Serial No. 63 / 175,548, titled "System and Method for Secure End-To-End Electronic Communication Using a Privately Shared Table of Entropy", filed on April 15, 2021, each of which is incorporated herein by reference in its entirety.
[0003] This application relates to U.S. Patent Application Serial No. 16 / 823,286, titled "Electromechanical Apparatus, System, and Method for Generating True Random Numbers", filed on March 18, 2020, which is incorporated herein by reference in its entirety.
[0004] Technical Field of the Invention
[0005] This application generally relates to secure communications, including but not limited to secure communications using a mutating table that includes the entropy of random numbers.
[0006] Background
[0007] Random number generation is a key component of computer and Internet security and enables encrypted end-to-end communications. The problems with security systems that utilize a pseudorandom number generator (e.g., a seeded computational algorithm or deterministic logic) are well known. For example, if the seed value is known, the entire random sequence generated by the pseudorandom number generator can be reproduced, allowing an unauthorized party to breach the security of the system.
[0008] Overview
[0009] Accordingly, there is a need for secure communication methods and systems that can efficiently and securely transfer information between devices (e.g., electronic devices) within a system.
[0010] One way to ensure the integrity and security of a computerized network is to utilize keys created from truly randomly generated numbers (e.g., true random numbers). Embodiments herein solve the problem of providing a secure network by encrypting and decrypting data transmitted between devices of a secure communication network using a privately shared entropy table (e.g., a privacy table). The entropy table includes true (e.g., true) random numbers. Additionally, the entropy table can be mutated (e.g., using a current digest) to create a new value for each entry in the table (e.g., triggered based on the number of uses or a specific time period). A mutation protocol (e.g., a predefined hash algorithm, a keyed hash, and / or other cipher) can be distributed (e.g., separately from the distribution of the table) to each user of the entropy table such that each user device can mutate the table in the same way. In some embodiments, the mutation protocol includes one or more ciphers (e.g., an encryption cipher that matches the block size of the elements to be matched).
[0011] In some cases, the use of a mutation protocol improves security and privacy by considering the possible theft of the entropy table or the current digest of the entropy table. For example, if a security issue is raised, it allows users of the entropy table to move to a new entropy table. In some embodiments, for resynchronization after the sender has mutated the entropy table, other users attempt to decrypt a message from the sender, and if the decryption fails, the mutation protocol is used to mutate the table and the decryption is attempted again. In some embodiments, a version number is stored with each entropy table and transmitted with the message to improve the performance of synchronizing the entropy tables.
[0012] The transformation of the privacy table also inhibits the reverse engineering of encryption keys. For example, consider a scenario where hundreds of drones are employed in a conflict. During the conflict, some drones may be disabled and captured by hostile forces. The hostile forces may perform reverse engineering on the drones and discover the privacy table. In such a case, the hostile forces can only potentially use the privacy table to decrypt / encrypt messages for a specific drone (since each drone has a different privacy table). Additionally, the privacy table for a specific drone may be insufficient as the drone owner may transform the privacy table before the privacy table can be used by the hostile forces for communication.
[0013] In some embodiments, the corresponding entropy table is stored with each application that uses it. In some embodiments, a container is used to store one or more entropy tables and one or more transformations of each table (e.g., to reduce real-time processing requirements and improve decryption time). In some embodiments, the container is protected with a key such as a fingerprint, a token, or a time-based one-time password (TOTP).
[0014] In some embodiments, random numbers are generated using electromechanical devices that can be installed in a conventional data center. In some embodiments, the generated random numbers can be used to provide entropy as a service (EAAS). For example, EAAS can provide random numbers for generating an entropy table that can be privately shared among devices in a secure communication network (e.g., a secure communication system) for secure communication and the transmission of information (e.g., data). In some embodiments, EAAS is provided from a security provider to a third party (e.g., a third-party service provider or a third-party server that hosts a network or a service) to ensure secure data transmission between devices.
[0015] According to some embodiments, a method is performed at a first electronic device (e.g., a transmitter device). The first electronic device: (i) obtains a first version of a privacy table that includes N first bits; (ii) applies a predefined hash algorithm to the first version of the privacy table to generate a second version of the privacy table having N second bits; (iii) obtains a first message for transmission to a second electronic device that (a) has a copy of the first version of the privacy table and (b) has access to the predefined hash algorithm; (iv) generates a master key based on the second version of the privacy table; (v) encrypts the first message using the master key to form an encrypted first message; and (vi) transmits the encrypted first message and a version identifier for the second version of the privacy table to the second electronic device.
[0016] In some embodiments, a computing device includes one or more processors, a memory, and one or more programs stored in the memory. The programs are configured to be executed by the one or more processors. The one or more programs include instructions for performing (or causing the performance of) any of the methods described herein.
[0017] In some embodiments, a non-transitory computer-readable storage medium stores one or more programs configured for execution by a computing device having one or more processors and a memory. The one or more programs include instructions for performing (or causing the performance of) any of the methods described herein.
[0018] Thus, the methods and systems disclosed herein provide secure communication using a mutation table that includes the entropy of true random numbers. Such methods and systems can supplement or replace conventional methods for secure communication.
[0019] The features and advantages described in this specification are not necessarily all-inclusive, and in particular, given the figures, specification, and claims provided in this disclosure, some additional features and advantages will be apparent to those of ordinary skill in the art. Additionally, it should be noted that the language used in the specification was primarily selected for readability and guidance purposes and not necessarily for defining or limiting the subject matter described herein. Brief Description of the Drawings
[0021] To better understand the various embodiments described, reference should be made to the following description of the embodiments in conjunction with the following drawings, in which like reference numerals refer to corresponding parts throughout the drawings and the specification.
[0022] Figure 1 An example secure communication system according to some embodiments is shown.
[0023] Figure 2 is a block diagram of an example electronic device of a secure communication system according to some embodiments.
[0024] Figure 3A and Figure 3B shows secure communication between two devices of a secure communication system according to some embodiments.
[0025] Figure 3C shows generation of a master key based on a mapping and a privacy table according to some embodiments.
[0026] Figure 4A An example of encrypting a payload according to some embodiments is shown.
[0027] Figure 4B An example of encrypting a real-time stream according to some embodiments is provided.
[0028] Figure 5 Provided is an example secure communication system with a drone and a landing station according to some embodiments.
[0029] Figure 6A and Figure 6B Illustrated is secure communication between two devices of a secure communication system according to some embodiments.
[0030] Figure 7A and Figure 7B Provided is an example of an encrypted payload according to some embodiments.
[0031] Figure 7C Provided is an example transformation protocol according to some embodiments.
[0032] Figures 8A to 8C Provided is a flowchart of a method for secure communication according to some embodiments.
[0033] Figure 9 Provided is a flowchart of a method for secure communication according to some embodiments.
[0034] Description of Embodiments
[0035] Reference will now be made to embodiments, examples of which are illustrated in the accompanying drawings. In the following description, numerous specific details are set forth in order to provide an understanding of the various described embodiments. However, it will be apparent to one of ordinary skill in the art that the various described embodiments may be practiced without these specific details. In other instances, well-known methods, procedures, components, circuits, and networks have not been described in detail so as not to unnecessarily obscure aspects of the embodiments.
[0036] Entropy (randomness) is important for strong cryptographic systems. Entropy created using a true random number generator (RNG) provides stronger encryption (e.g., an unpredictable key). One-time pad (OTP) is a strong encryption technique, but requires a pre-shared key that is at least as long as the message being sent and is used only once. The generated ciphertext is essentially impossible to decrypt as long as the following conditions are met: (i) the key must be at least as long as the plaintext; (ii) the key must be random; (iii) the key must not be reused in whole or in part; and (iv) the key must be kept completely secret by both parties. However, secure key exchange is a challenge, especially when using OTP. Since each key can only be used once, providing the key becomes both cumbersome and a potential weakness in security.
[0037] As described herein, a privacy table (e.g., an entropy table) can be used to generate keys. One method of creating a key using a privacy table includes: (1) selecting a point in the privacy table; (2) determining which bits are to be extracted for the key (e.g., the key spans multiple cells in the table); (3) creating the key and a key map that describes to the recipient how to recreate the key; (4) encrypting a plaintext message with the key to generate a ciphertext; and (5) sending the key map and the ciphertext to the recipient. In this example, the recipient uses the key map and a copy of the recipient's privacy table to recreate the key and then uses the recreated key to decrypt the ciphertext.
[0038] As an example, some autonomous vehicles (e.g., drones) and landing stations (sometimes also referred to as docking stations or control stations) use barcodes to identify each other (e.g., two-dimensional barcodes such as QR codes). However, the problem with static barcodes is that the codes can be copied and used in an unauthorized manner (e.g., introducing an unauthorized drone or landing station into the system). Dynamic electronic barcodes (e.g., OTP barcodes) help prevent copying, especially if the dynamic barcode is generated using true random numbers.
[0039] For example, when a drone and a landing station are connected, each can display a QR code containing an encrypted authentication message on its (e-paper) display. The QR code can be generated from a shared privacy table, as described in detail later. Then, both the landing station and the drone can decrypt the corresponding authentication message and verify that the other is authorized. Additionally, after each is authenticated, additional secure messages can be exchanged using OTP. However, for example, if the drone fails to authenticate the docking station, it can be programmed to fly away and / or delete its memory (effectively disabling the drone). In the case of multiple drones, each additional drone can have a corresponding privacy table and be provided to the docking station. In these cases, the docking station stores multiple privacy tables and may have to try several privacy tables in order to authenticate a particular drone.
[0040] Example authentication messages from a drone can include one or more of the following: drone serial number, current status, and amount of data to be transmitted. Example authentication messages from a landing station can include one or more of the following: station serial number, wireless password, and one or more commands.
[0041] Now turning to the drawings, Figure 1FIG. 0 is a block diagram of a secure communication system 100 (e.g., a secure communication network) according to some embodiments. The secure communication system 100 includes a plurality of devices (e.g., electronic devices such as devices 110, 120, 130, and 140) that can communicate securely with each other. The secure communication system 100 includes an electronic device 110, an electronic device 120, and a security log 112. In some embodiments, the secure communication system 100 includes additional devices (such as electronic devices 130 and 140) that can communicate with other devices in the secure communication system 100. In this example, the electronic device 110 is shown as being capable of communicating with a plurality of devices (e.g., devices 120, 130, or 140).
[0042] In some embodiments, data transmitted to and / or from the electronic device 110 is stored in the security log 112. In some embodiments, the security log 112 is a blockchain ledger for recording all data sent and / or received at the electronic device 110. In some embodiments, the security log 112 is a permissioned blockchain network. In some embodiments, the security log 112 is stored at another electronic device different from the electronic device 110. For example, the security log 112 can be stored at a computer system or a server system.
[0043] The secure communication system 100 can include any number of devices and be oriented to any application area. For example, the secure communication system 100 can include one or more IoT devices such as smartphones, smart appliances (e.g., smart refrigerators or smart thermostats), smart fire alarms, smart doorbells, smart locks, smart machines (e.g., smart cars, smart bicycles, or smart scooters), smart wearable devices (e.g., smart fitness trackers or smart watches), smart lighting (e.g., smart light bulbs or smart plugs), smart assistant devices, and smart security systems (e.g., smart cameras, smart pet monitors, or smart baby monitors). For example, a user with a smartphone can have an application that communicates with a smart refrigerator, a smart thermostat, one or more smart light bulbs, and a smart watch. Each of these smart devices (e.g., IoT devices) is capable of communicating with the smartphone via the secure communication system 100 using the methods described herein.
[0044] Figure 2 FIG. 10 is a block diagram of a computer system 200 according to some embodiments. In some embodiments, Figure 1The electronic device 110 therein is an example of the computer system 200. The computer system 200 includes one or more processors 210 (e.g., CPU, microprocessor, or processing unit), a communication interface 212, a memory 220, and one or more communication buses 214 for interconnecting these components (sometimes referred to as a chipset). In some embodiments, the computer system 200 includes or communicates with a random number generation system 216 that is configured to generate random numbers and provide the random numbers to the computer system 200 (e.g., to a device of the computer system, such as the electronic device 110). In some embodiments, the random number generation system 216 includes a random number generation device and one or more modules for controlling the random number generation device and recording the generated random numbers. For example, the random number generation device may be a physical random number generation device, and the one or more modules may include an image processor for processing images from the physical random number generation device. Examples of the random number generation device are disclosed in U.S. Patent Application Serial No. 16 / 823,286, filed on March 18, 2020, which is incorporated herein by reference in its entirety.
[0045] In some embodiments, the memory 220 in the computer system 200 includes high-speed random access memory, such as DRAM, SRAM, DDR SRAM, or other random access solid-state memory devices. In some embodiments, the memory includes non-volatile memory, such as one or more disk storage devices, one or more optical disk storage devices, one or more flash memory devices, or one or more other non-volatile solid-state storage devices. The memory, or alternatively, the non-volatile memory within the memory, includes a non-transitory computer-readable storage medium. In some embodiments, the memory or the non-transitory computer-readable storage medium of the memory stores the following programs, modules, and data structures, or subsets or supersets thereof:
[0046] An operation logic 222, which includes programs for processing various basic system services and for performing hardware-related tasks;
[0047] A communication module 224, which is coupled to and / or communicates with remote devices and remote systems (e.g., the random number generation system 216, the database 240, and / or other wearable, IoT, or smart devices) in combination with the communication interface 212;
[0048] A request processing module 226, which processes requests for random number generation;
[0049] A privacy table module 228, which manages a privacy table (also referred to as a table of entropy or entropy table). In some embodiments, the privacy table module 228 generates, stores, transforms, and transmits the table. In some embodiments, the privacy table module 228 includes:
[0050] A table generation module 229 that generates a privacy table (e.g., including random numbers) based on information received from a random number generation system 216. In some embodiments, an entropy block including random numbers is used to generate the privacy table; and
[0051] A table transformation module 231 that transforms the privacy table according to a transformation protocol (e.g., a predefined hashing algorithm). In some embodiments, the table transformation module 231 maintains and / or removes privacy table versions according to a transformation protocol (or user or system preferences);
[0052] A mapping generation module 230 that generates a mapping (e.g., an encoding / decoding mapping) based on the privacy table;
[0053] A master key generation module 232 that generates a master key based on the mapping and the privacy table. In some embodiments, generating the master key includes applying a digest function to a string;
[0054] An encryption module 234 that encrypts a message to be transmitted (e.g., data or text). For example, the encryption module 234 may encrypt patient information before transmitting it to an electronic device 120 that communicates with a device of the computer system 200 (such as the electronic device 110). In some embodiments, the encryption module 234 uses the master key generated by the master key generation module 232 to encrypt the message;
[0055] A decryption module 236 that decrypts a message (e.g., data or text) received from another device that communicates with a device of the computer system 200. For example, the decryption module 236 is capable of generating (e.g., recreating) a relevant master key based on the received information and using the master key to decrypt the message; and
[0056] A database 240 that stores:
[0057] Previously generated random numbers 242 (e.g., stored as a sequence of bytes, 64-bit blocks, or 256-bit blocks). This is also referred to as an entropy cache. In some embodiments, the entropy within the privacy table is not reused;
[0058] Data 244 sent and / or received by a device of the computer system 200 (such as the electronic device 110). In some embodiments, the data 244 is transmitted to a security log 112; and
[0059] Blockchain information (e.g., a ledger) 246 about the privacy table obtained (e.g., generated or received) via the privacy table module 228.
[0060] In some embodiments, computer system 200 is a computing device that executes an application (e.g., an entropy application) to process data (e.g., random numbers) from random number generation device 216. In some embodiments, computer system 200 uses communication interface 212 to send instructions to database 240 to retrieve random numbers 242 (e.g., from an entropy cache). In response to receiving the instructions, database 240 may return random numbers 242 via interface 212. In some embodiments, the random numbers 242 stored in database 240 are associated with one or more random numbers generated by random number generation device 216.
[0061] Computer system 200 may be implemented as any type of computing device, such as a system-on-chip, a microcontroller, a console, a desktop or laptop computer, a server computer, a tablet, a smart phone, or other mobile device. Accordingly, computer system 200 includes components common to typical computing devices, such as a processor, random access memory, storage devices, network interfaces, I / O interfaces, etc. The processor may be or include one or more microprocessors or application specific integrated circuits (ASICs). The memory may include RAM, ROM, DRAM, SRAM, and MRAM, and may include the processor and firmware, such as static data or fixed instructions, BIOS, system functions, configuration data, and other routines used during operation of the computing device. The memory also provides a storage area for data and instructions associated with the applications and data processed by the processor.
[0062] The storage device provides non-volatile, bulk, or long-term storage of data or instructions in the computing device. The storage device may take the form of magnetic or solid state disks, tapes, CDs, DVDs, or other reasonably high-capacity addressable or serial storage media. Multiple storage devices may be provided to or available for the computing device. Some of these storage devices may be external to the computing device, such as network storage or cloud-based storage. The network interface includes an interface to a network and may be implemented as a wired or wireless interface. The I / O interface connects the processor to peripheral devices (not shown), such as sensors, displays, cameras, color sensors, microphones, keyboards, and / or USB devices.
[0063] Attention is now directed to embodiments of secure transmission of data between devices of secure communication system 100.
[0064] Figures 3A to 3C Shown is secure communication between two devices (e.g., electronic devices 302 and 304, two different devices from each other) of secure communication system 100 according to some embodiments. Each of electronic devices 302 and 304 may be an instance of electronic device 110, 120, 130, or 140, or be associated with Figure 1An electronic device associated with the security log 112 shown in. For example, the first electronic device 302 may correspond to the first electronic device 110, and the second electronic device 304 may correspond to the second electronic device 120, or vice versa. In another example, the first electronic device 302 may correspond to the first electronic device 110, and the second electronic device 304 may correspond to an electronic device that is part of a computer system or server system that stores the security log 112, or vice versa.
[0065] When the secure communication system 100 includes a medical network, each of the electronic devices 302 and 304 may correspond to any one of the following: a patient device, a device of a remote monitoring system, a device associated with a database, or a device associated with a healthcare provider (e.g., a doctor, a clinic, or a hospital). When the secure communication system 100 includes a drone network, each of the electronic devices 302 and 304 may correspond to any one of a drone, a landing station, a control station, or a device associated with a drone facility.
[0066] The electronic device 302 stores a privacy table 310 (e.g., an entropy table) consisting of random bits. The electronic device 302 transmits (operation 1) the privacy table 310 to the electronic device 304 via an encrypted channel, and the electronic device 304 stores the transmitted privacy table 310. The electronic device 302 generates (operation 2) a mapping 312 (e.g., an encoding / decoding mapping 312) and generates (operation 3a) a master key 316 (e.g., an encryption key) based on the mapping 312 (e.g., the values in the mapping 312) and the random numbers (e.g., bits) stored in the privacy table 310. In some embodiments, the electronic device 302 also generates (operation 3b) a challenge string 314 based on the master key 316 (e.g., the challenge string 314 is derived from the master key 316). In some embodiments, the challenge string 314 is transmitted from the electronic device 302 to the electronic device 304 separately from any one of the mapping 312, the master key 316, and the encrypted message (e.g., out-of-band transmission), and is used by the electronic device 304 to verify that the master key 316 is correctly recreated and the transmitted information can be trusted. In some embodiments, the electronic device 302 applies a hash function (such as SHA256) to the master key 316 to generate (operation 3b) the challenge string 314. For example, the master key 316 is a hash of the challenge string 314, such as a SHA256 hash.
[0067] In some embodiments, the mapping 312 includes information on how to use the privacy table 310 to generate the master key 316 and / or the challenge string 314. For example, the values in the mapping 312 correspond to any one of the following: a starting position in the privacy table, an offset value, and a reading direction. Below regarding Figure 4A and Figure 4BAdditional details regarding the mapping 312 are provided. In some embodiments, a subset or portion (less than all) of the random numbers (e.g., bits) stored in the privacy table 310 is used to generate the mapping 312. In some embodiments, a subset or portion (less than all) of the random numbers (e.g., bits) stored in the privacy table 310 is used to generate the master key 316 and the challenge string 314. In some embodiments, the mapping 312 does not include information (e.g., an identifier) regarding which privacy table it is associated with (e.g., from which privacy table it is generated).
[0068] The electronic device 302 encrypts (operation 4) the first message 320 (e.g., data) using the master key 316 to form the encrypted first message 322. For example, the electronic device 302 may use a symmetric cipher, such as AES-256 (which is a symmetric cipher that encrypts in blocks of 256 bits), to encrypt the first message 320. The electronic device 302 generates (operation 5) an encrypted payload 324 (also referred to as ciphertext) that includes the mapping 312 and the encrypted first message 322. In some embodiments, the encrypted payload 324 includes the mapping 312 prefixed to the encrypted first message 322. In some embodiments, such as when using a symmetric cipher, the master key 316 is a symmetric key (e.g., the same master key can be used to encrypt a message to form an encrypted message and to decrypt the encrypted message to recreate the original message). Regarding Figure 4A and Figure 4B Examples of the encrypted payload 324 are provided. Examples of symmetric ciphers include (but are not limited to): AES, Blowfish, RC4, Twofish, Serpent, Camellia, Salsa20, ChaCha20, CAST5, Kuznyechik, DES, 3DES, Skipjack, Safer, and IDEA. In some embodiments, the cipher used to encrypt a message is determined (e.g., selected) based on the period of time for which the information stored in the message needs to be kept secure. For example, if the information stored in the encrypted message expires (e.g., becomes irrelevant) within 30 seconds, a first symmetric cipher (e.g., RC4) may be used to encrypt the message. Conversely, if the information stored in the encrypted message needs to be kept secure for a long period of time (e.g., several months, years, or permanently), a different symmetric cipher may be used to encrypt the message.
[0069] The electronic device 302 transmits (operation 6) an encrypted payload 324 (which includes a mapping 312 and an encrypted first message 322) to the electronic device 304. Since the message is encrypted, the transmission does not need to be over an encrypted or secure channel. The encrypted payload 324 is transmitted (in operation 6) at a time different from the time at which the privacy table 310 is transmitted (in operation 1). For example, the encrypted payload 324 is transmitted after the privacy table 310 is transmitted (e.g., the privacy table 310 is transmitted as part of a different payload than the encrypted payload 324).
[0070] The electronic device 304 receives the encrypted payload 324 (which includes the mapping 312 and the encrypted first message 322) from the electronic device 302, and reads (e.g., extracts or determines) (operation 7) the mapping 312 (e.g., an encoding / decoding mapping) from the encrypted payload 324. The electronic device 304 then uses the information from the mapping 312 and the privacy table 310 to recreate (operation 8) the challenge string 314 (e.g., generate a recreated challenge string 314′) and the master key 316 (e.g., generate a recreated master key 316′). In some embodiments, the challenge string 314 is derived from the master key 316 (and thus, the recreated challenge string 314′ can be derived from the recreated master key 316′). In some embodiments, the recreated challenge string 314′ is the same (e.g., identical) as the challenge string 314. The electronic device 304 uses the recreated challenge string 314′ to verify (operation 9) the master key 316 (e.g., generate a recreated master key 316′), and uses the recreated master key 316′ to decrypt (operation 10) the encrypted first message 322 in the encrypted payload 324 to form a decrypted first message 326. The electronic device 302 then initializes a decryption protocol (e.g., a decryption algorithm, such as AES256) corresponding to the encryption protocol used to encrypt the message with the recreated master key 316', and decrypts the encrypted first message 322 to form a decrypted first message 326.
[0071] In some embodiments, the recreated master key 316′ is the same (e.g., identical) as the master key 316. For example, in some embodiments, such as when the first message 320 is encrypted using a symmetric cipher (such as AES-256), the recreated master key 316′ that is identical to the master key 316 used to encrypt the first message 320 to form the encrypted first message 322 can be used to decrypt the encrypted first message 322.
[0072] In some embodiments, the process described in Figure 3A (e.g., operations 2 to 10) is repeated for each new message sent from the electronic device 302 to the electronic device 304. As Figure 3BAs shown, for the transmission of the second message 340, the electronic device 302 generates a new mapping 332 (e.g., an encoding / decoding mapping 332) for the second message 340 such that the second message 340 is encrypted based on (e.g., using) a new master key 336 that is different (e.g., not the same) from the master key 316 used to encrypt the first message 320 (e.g., the previously transmitted message). Figure 3A The processes (e.g., operations 1 to 10) described in Figure 3A are cipher-agnostic and can be performed using any encryption protocol (and any decryption protocol).
[0073] Figure 3B A process for securely transmitting a second message 340 different from the first message 320 from the electronic device 302 to the electronic device 304 is shown. The electronic device 302 generates (operation 11) a new mapping 332 (e.g., an encoding / decoding mapping 332) that is different (e.g., not the same) from the mapping 312. The electronic device 302 also generates (operation 12a) a new master key 336 (e.g., an encryption key) based on the mapping 312 and a random number (e.g., bits) stored in the privacy table 310. In some embodiments, the electronic device 302 generates (operation 12b) a new challenge string 334 from the master key 336. Since the new mapping 332 is different from the mapping 312, the new master key 336 is different from the master key 316 (e.g., not the same), and the new challenge string 334 is different from the challenge string 314 (e.g., not the same).
[0074] The electronic device 302 encrypts (operation 13) the second message 340 (e.g., data) using the new master key 336 to form an encrypted second message 342. The electronic device 302 generates (operation 14) a new encrypted payload 344 that includes the new mapping 332 and the encrypted second message 342. In some embodiments, the new encrypted payload 344 includes the mapping 332 prefixed to (or appended to) the encrypted second message 342.
[0075] The electronic device 302 transmits (operation 15) the new encrypted payload 344 (which includes the new mapping 332 and the encrypted second message 342) to the electronic device 304 (e.g., via an encrypted channel). The new encrypted payload 344 is transmitted (in operation 15) at a time different from the transmission time of the privacy table 310 (in operation 1) and at a time different from the transmission time of the encrypted payload 324 (in operation 6).
[0076] The electronic device 304 receives the new encrypted payload 344 (which includes the new mapping 332 and the encrypted second message 342) from the electronic device 302, and reads (e.g., extracts or determines) (operation 16) the new mapping 332 from the new encrypted payload 344. Then, the electronic device 304 uses the information from the new mapping 332 and the privacy table 310 to recreate (operation 17) the new master key 336 (e.g., generate the recreated new master key 336'). In embodiments where the electronic device 304 receives the new challenge string 334, the electronic device 304 uses the information from the new mapping 332 to recreate the challenge string 334 (e.g., generate the recreated challenge string 334'). In some embodiments, the electronic device 304 uses the recreated challenge string 334' to verify (operation 18) the new master key 336. The electronic device 304 uses the recreated master key 336' to decrypt (operation 19) the second encrypted message 342 in the new encrypted payload 344 to form the decrypted second message 346.
[0077] In some embodiments, the electronic device updates the privacy table 310 with a new privacy table. The new privacy table can be transmitted using the secure message transmission process described above with respect to Figure 3A and Figure 3B described secure message transmission processes.
[0078] In some embodiments, the privacy table (such as the privacy table 310) is generated by the random number generation system 216. In some embodiments, the privacy table is generated by the computer system 200 (e.g., by a device of the computer system 200, such as the electronic device 302) using random numbers generated by the random number generation system 216. In some embodiments, generating the privacy table includes determining the number of required keys for a predefined time period and determining the size of the privacy table based on the number of required keys. In some embodiments, the predefined time period corresponds to a time interval (e.g., a predefined time interval) for replenishing the privacy table. The size of the new privacy table can be the same as or different from the size of the old privacy table (e.g., the same if the requirements are the same, or different if the expected requirements are different). In some embodiments, the privacy tables stored at the devices (such as devices 302 and 304) of the secure communication system 100 are updated (e.g., replenished) at predefined intervals (e.g., after a predefined time period). In some embodiments, updating the privacy table includes updating (e.g., replenishing) the entire privacy table (e.g., replacing all the random numbers (e.g., bits) stored in the privacy table with new random numbers (e.g., new bits)). In some embodiments, updating the privacy table includes updating (e.g., replenishing) a subset or a portion (less than all) of the random numbers (e.g., bits) in the privacy table. In some embodiments, only the random numbers (e.g., bits) that have been used (e.g., have been read) are replaced (e.g., replenished), and the other numbers stored in the privacy table that have not been used remain unchanged.
[0079] Figure 3C Illustrates generating master key 316 based on a mapping (e.g., encoding / decoding mapping 312) and a privacy table (e.g., privacy table 310) according to some embodiments. The mapping 312 is generated based on random numbers (e.g., bits) stored in the privacy table 310 (operation 2a). In some embodiments, generating the mapping 312 includes identifying a starting position and a reading direction (e.g., rotation) within the privacy table 310. In some embodiments, the starting position is randomly selected (e.g., using a pseudo-random number generator). In some embodiments, the reading direction is randomly selected (e.g., using a pseudo-random number generator). The mapping 312 is generated by starting to read the random numbers (e.g., bits) in the privacy table 310 at the starting position and reading the random numbers (e.g., bits) stored in the privacy table 310 in the reading direction.
[0080] The master key 316 is generated based on the values in the mapping 312 (e.g., the random numbers constituting the mapping 312) and the random numbers (e.g., bits) stored in the privacy table 310 (operation 3a). In some embodiments, a challenge string 314 is generated based on the master key 316 (e.g., derived from the master key 316) (operation 3b). The master key 316 is used to encrypt (operation 4b) messages. For example, to encrypt a message, the electronic device 302 may initialize an encryption protocol (e.g., an encryption algorithm such as AES256) that uses the master key 316 to encrypt the message and form an encrypted message.
[0081] In some embodiments, the process of securely transmitting the encrypted message 322 includes generating (operation 4a) an initialization vector 350 and using the initialization vector 350 in combination with the master key 316 to encrypt the message 320. For example, when the transmitted message 322 is part of a real-time stream that is a continuous transmission of multiple messages (or a continuous transmission of multiple payloads 324), each message is encrypted using a unique master key 316. In some embodiments, this also includes a unique initialization vector 350. In some embodiments, the initialization vector 350 is automatically updated (when included) for each new message 320 to be encrypted (e.g., a new initialization vector 350 is automatically created).
[0082] In some embodiments, the electronic device 302 shares a particular privacy table with no more than one device (e.g., shares privacy table 310 with only one electronic device 304). In such a case, if the electronic device 302 needs to communicate securely with multiple different devices (e.g., with the electronic device 304 and at least one other electronic device different from the electronic device 304), the electronic device 302 stores multiple privacy tables such that messages transmitted to different devices are encrypted based on (e.g., using) different privacy tables. For example, a master key for encrypting messages to be transmitted to the electronic device 302 is generated based on a mapping and a first privacy table, and a master key for encrypting messages (which may be the same message or a different message) to be transmitted to another electronic device different from the electronic device 302 is generated based on the mapping and a second privacy table different from the first privacy table. In some embodiments, the electronic device 302 shares the same privacy table with more than one device. For example, the electronic device 302 may share the same privacy table with the electronic device 304 and two other devices. In such a case, all devices storing the privacy table (e.g., the electronic device 302, the electronic device 304, and the two other devices) may communicate securely with each other via the secure communication process described above with respect to Figures 3A to 3C described.
[0083] Figure 4A FIG. shows an example of an encrypted payload 324 according to some embodiments. In Figure 4A , the encrypted payload 324-A includes an encrypted first message 322 and a mapping 312. For example, the encrypted payload 324-A is a concatenation of the encrypted first message 322 and the mapping 312. The values (e.g., numerical values) in the mapping 312 are presented by the letters "A" through "G" in Figure 4A . According to some embodiments, in Figure 4A , the mapping 312 is prefixed to the encrypted first message 322.
[0084] In some embodiments, the mapping 312 is used to generate a challenge string 314 and thus includes multiple values corresponding to instructions or directions on how to use the privacy table to generate (or recreate) the challenge string. For example, the mapping 312 includes one or more of the following:
[0085] A random value (e.g., a numerical value) corresponding to a starting point within the privacy table, represented by the letter "A";
[0086] A value (e.g., a numerical value) corresponding to a horizontal offset starting from the starting point within the privacy table, represented by the letter "B";
[0087] A value (e.g., a positive or negative value) corresponding to a horizontal read direction starting from the starting point within the privacy table;
[0088] The value (e.g., numerical value) corresponding to the vertical offset starting from the starting point within the privacy table is represented by the letter "C";
[0089] The value (e.g., positive or negative value) corresponding to the horizontal reading direction starting from the starting point within the privacy table;
[0090] The value (e.g., numerical value) corresponding to the size of the privacy table in the horizontal direction (e.g., the arrangement of the size) is represented by the letter "D";
[0091] The value (e.g., numerical value) corresponding to the size of the privacy table in the vertical direction (e.g., the arrangement of the size) is represented by the letter "E";
[0092] The value (e.g., numerical value) corresponding to the starting point within the privacy table (e.g., within the arrangement) is represented by the letter "F". In some embodiments, the value corresponding to the starting point within the privacy table is defined by the size of the privacy table. In some embodiments, the value corresponding to the starting point within the privacy table is generated by a pseudo-random number generator; and
[0093] The length of the challenge string used to generate the master key is represented by the letter "G". In some embodiments, the length of the challenge string is based on the size of the master key (which can be, for example, 246 bits of length 32 bytes).
[0094] In some embodiments, the random value "A" is generated (e.g., provided) by a pseudo-random number generator. In some embodiments, the random value "A" is selected from a set of values determined based on the size of the privacy table 310. For example, when the privacy table 310 is a 2D matrix with a size of 100×50 (e.g., "D" = 100 and "E" = 50) and stores a total of 5000 values, 0 ≤ A ≤ 5000.
[0095] The privacy table 310 can include any number of random numbers. In some embodiments, the privacy table 310 consists of as few as 256 bits. In some embodiments, the privacy table 310 includes 10,000 or more random bits. In some embodiments, the size of the privacy table 310 is determined based on the intended use of the privacy table. For example, if the privacy table 310 has an intended use of a few seconds (e.g., as part of a process for encrypting voice between two parties), a privacy table 310 with a small size is sufficient.
[0096] For a privacy table 310 including 10,000 bits, the generation of the mapping 312 can include any of the following:
[0097] Obtaining a random value "A" using a pseudo-random number generator, where 1 ≤ A ≤ 10,000. In this example, A = 2544;
[0098] Obtain a random value "B" corresponding to a horizontal offset starting from a starting point within the privacy table, where 1 ≤ B ≤ 10000. In some embodiments, "B" is obtained via a pseudo-random number generator;
[0099] Obtain a randomly determined direction corresponding to a horizontal reading direction (e.g., a positive reading direction or a negative reading direction);
[0100] Obtain a random value "C" corresponding to a vertical offset starting from a starting point within the privacy table, where 1 ≤ C ≤ 10000. In some embodiments, "C" is obtained via a pseudo-random number generator;
[0101] Obtain a randomly determined direction corresponding to a vertical reading direction (e.g., a positive reading direction or a negative reading direction);
[0102] Calculate a horizontal arrangement value "D", which corresponds to the size of the privacy table 310 in the horizontal direction. For example, the horizontal arrangement value is determined (e.g., calculated) by arranging all values between 1 and the size of the privacy table in the horizontal direction; and
[0103] Calculate a vertical arrangement value "E", which corresponds to the size of the privacy table 310 in the vertical direction. For example, the vertical arrangement value is determined (e.g., calculated) by arranging all values between 1 and the size of the privacy table in the vertical direction.
[0104] Figure 4B An example of a real-time stream 360 according to some embodiments is provided. The real-time stream 360 includes a plurality of encrypted payloads 410, which are transmitted sequentially (e.g., in order) from each other. Each encrypted payload 410 in the plurality of encrypted payloads includes a corresponding encrypted message 364 corresponding to a part of the real-time stream 360 and a corresponding mapping 312 (represented by letters "A" to "G") corresponding to a corresponding master key 316 for the corresponding encrypted message 364. In some embodiments, the encrypted payload 410 includes a corresponding initialization vector 350 (represented by "H"), which is used in combination with the corresponding master key 316 to form the corresponding encrypted message 364. This example shows the transmission of two encrypted messages 364-1 and 364-2 corresponding to the first two messages of the real-time stream 360. The transmission of the first payload 410-1 (e.g., the encrypted payload) includes the first encrypted message 364-1 ("encrypted message 1") and the mapping 312-1 (e.g., the encoding / decoding mapping) corresponding to the first encrypted message 364-1 (e.g., "A1" to "G1", each representing as regarding Figure 4AThe described numerical value). In some embodiments, the first payload 410-1 includes an initialization vector 350-1 corresponding to the first encrypted message 364-1 (e.g., "H1"). For example, the encrypted payload 410-1 (also known as the ciphertext) is a concatenation of the encrypted message 364-1, the mapping 312-1, and an optional initialization vector 350-1. In some embodiments, as shown, the mapping 312-1 is prefixed to the encrypted first message 364-1. In some embodiments, the optional initialization vector 350-1 is appended to the encrypted first message 364-1 (e.g., the optional initialization vector 350-1 is added at the end or after the encrypted message 364-1).
[0105] The second payload 410-2 (e.g., encrypted payload) directly following the first payload 410-1 is transmitted (and desirably received) sequentially with the transmission (and reception) of the first payload 410-1. The transmission of the second payload 410-2 includes a second encrypted message 364-2 ("encrypted message 2") and a mapping 312-2 corresponding to the second encrypted message 364-2 (e.g., encoding / decoding mapping) (e.g., "A2" to "G2", each representing a numerical value as described with respect to Figure 4A The described numerical value). In some embodiments, the second payload 410-2 further includes an initialization vector 350-2 corresponding to the second encrypted message 364-2 (e.g., "H2"). Additional messages 364 of the real-time stream 360 can be sent (and received) continuously in this manner until the real-time stream 360 ends.
[0106] Thus, in some embodiments, the process of encrypting messages as part of a real-time stream includes generating an initialization vector 350, generating a challenge string 314, and generating a master key 316. Examples of the initialization vector 350, if used to encrypt messages in the real-time stream, are "58, 148, 100, 27, 59, 184, 8, 236, 189, 24, 21, 6, 113, 162, 244, 26, 59, 72, 222, 95, 188, 247, 143, 118, 97, 168, 187, 147, 24, 153, 96, 130", examples of the challenge string 312 are "FFFBFCCFEFFADAFFFFFBFFEFFFCEFFFF", and examples of the master key 316 are "186, 3, 235, 211, 177, 202, 35, 167, 225, 195, 16, 151, 164, 71, 93, 47, 2, 114, 233, 26, 143, 119, 31, 103, 185, 88, 203, 62, 3, 43, 175, 85".
[0107] Figure 5FIG. 0 shows an example secure communication system 100 with a drone and a landing station according to some embodiments. Figure 5 The secure communication system 100 in FIG. 1 includes a drone 502 (e.g., an electronic device 302) and a landing station 508 (e.g., an electronic device 304). The drone 502 includes a drone sensor 506 (e.g., a camera or an optical sensor) and a drone electronic barcode 504 (e.g., a two-dimensional barcode such as a QR code). The landing station 508 includes a station sensor 510 (e.g., a camera or an optical sensor) and a station electronic barcode 512. According to some embodiments, each of the sensors 506 and 510 is configured to identify and scan the corresponding barcodes 504 and 512. In some embodiments, each electronic barcode 504 and 512 is configured to display an encrypted payload (e.g., encrypted payload 324). In some embodiments, the encrypted payload presented via the drone electronic barcode 504 includes an identifier for the drone 502. In some embodiments, the encrypted payload presented via the station electronic barcode 512 includes an identifier for the landing station 508. In some embodiments, the encrypted payloads presented via the electronic barcodes 504 and 512 are encrypted using a shared privacy table (e.g., as will be discussed in more detail below with respect to Figure 6A and Figure 6B ).
[0108] Figure 6A and Figure 6B FIG. 12 shows secure communication between two devices (e.g., electronic devices 302 and 304, two different devices from each other) of the secure communication system 100 according to some embodiments. Figure 6A FIG. 14 shows an example operation occurring at the first electronic device 302, and Figure 6B FIG. 16 shows a corresponding example operation occurring at the second electronic device 304.
[0109] As Figure 6A shown, the first electronic device 302 stores a privacy table 310 (e.g., a first version of the privacy table) consisting of random bits and an associated deformation protocol 602. According to some embodiments, the deformation protocol 602 includes instructions for deforming the privacy table 310. In some embodiments, the deformation protocol 602 includes a predefined hashing algorithm (e.g., a secure hashing algorithm or a message digest algorithm). In some embodiments, the deformation protocol 602 includes information or instructions regarding the frequency (e.g., based on the elapsed time or the number of messages sent) of deforming the privacy table 310. In some embodiments, the deformation protocol 602 includes one or more parameters that can be set by a user to adjust how the privacy table is deformed. For example, a user can request deformation of the privacy table and input parameter values to set the type of hashing algorithm to be used for deforming the privacy table.
[0110] In some embodiments, the first electronic device 302 stores a first version 603 of the privacy table 310 (e.g., the first version 603 indicates that the privacy table 310 is the first version of the generated privacy table). In some embodiments, the first version 603 is an indication of the number of times the privacy table has been transformed (e.g., it is a value initially set to 0 or 1). In some embodiments, the first version 603 is included in the privacy table 310 (e.g., in addition to the random bits, the privacy table includes a value representing its version). In some embodiments, the first version 603 is stored in the blockchain ledger for the privacy table 310 (e.g., at the security log 112). In some embodiments, the first version 603 is not stored at the electronic device 302 (excluded), and the privacy table 310 does not have an indicator indicating its version. In embodiments without the first version 603, the receiver (e.g., the second electronic device 304) transforms the privacy table until the master key can be recreated (e.g., trial and error on different versions of the privacy table until a match is found).
[0111] The first electronic device 302 transmits (operation 1) the transformation protocol 602 to the second electronic device 304 via an encrypted channel. The second electronic device 304 transmits (operation 2) the privacy table 310 to the second electronic device 304 separately via an encrypted channel. In some embodiments, the first electronic device 302 transmits the transformation protocol 602 and the privacy table 310 to the second electronic device 304 in the same transmission.
[0112] The first electronic device 302 generates (operation 3) a mapping 312 (e.g., an encoding / decoding mapping) and generates (operation 3a) a master key 316 (e.g., an encryption key) based on the mapping 312 (e.g., the values in the mapping 312) and the random numbers (e.g., bits) stored in the privacy table 310. In some embodiments, the master key 316 is a digest of a challenge string, such as a SHA256 digest (e.g., as previously described with respect to Figure 3A ).
[0113] In some embodiments, the mapping 312 includes information on how to use the privacy table 310 to generate the master key 316. For example, the values in the mapping 312 can correspond to any one of a starting position, an offset value, and a read direction in the privacy table. As described above with respect to Figure 4A and Figure 4BAdditional details regarding mapping 312 are provided. In some embodiments, a subset or a portion (less than all) of the random numbers (e.g., bits) stored in privacy table 310 is used to generate mapping 312. In some embodiments, a subset or a portion (less than all) of the random numbers (e.g., bits) stored in privacy table 310 is used to generate master key 316. In some embodiments, mapping 312 does not include information (e.g., an identifier) regarding which privacy table it is associated with (e.g., from which privacy table it is generated).
[0114] The first electronic device 302 encrypts (operation 4) the first message 320 (e.g., data) using the master key 316 to form an encrypted message 322. For example, the first electronic device 302 may use a symmetric cipher, such as AES-256 (a symmetric cipher that encrypts in blocks of 256 bits), to encrypt the message 320. The first electronic device 302 generates (operation 5) an encrypted payload 324 (also referred to as ciphertext), which includes mapping 312 and the encrypted message 322, and in some embodiments generates a first version 603. In some embodiments, the encrypted payload 324 includes mapping 312 (and the first version 603) prefixed to or appended to the encrypted message 322. In some embodiments, such as when using a symmetric cipher, the master key 316 is a symmetric key. Regarding Figure 7A and Figure 7B An example of the encrypted payload 324 is provided. In some embodiments, the cipher used to encrypt the message is determined (e.g., selected) based on the transformation agreement 602. In some embodiments, the cipher used to encrypt the message is determined (e.g., selected) based on the period of time for which the information stored in the message needs to be kept secure.
[0115] The first electronic device 302 transmits (operation 6) the encrypted payload 324 to the electronic device 304. Since the message is encrypted, the transmission does not require an encrypted or secure channel. For example, in the context of a drone and landing station system, the encrypted payload 324 can be converted into a QR code that is visually displayed to the second electronic device 304. As Figure 6B shown, the encrypted payload 324 is transmitted (in operation 6) at a time different from the transmission times of the transformation agreement 602 (in operation 1) and the privacy table 310 (in operation 2). In some embodiments, the transformation agreement 602 and the privacy table 310 are transmitted via a first channel (e.g., an encrypted Wi-Fi channel), and the encrypted payload 324 is transmitted via a second channel different from the first channel (e.g., an unencrypted optical channel).
[0116] After transmitting the encrypted payload 324, the first electronic device 302 transforms (operation 7) the privacy table 310 based on a transformation protocol 602 to generate a second privacy table 604 (e.g., a second version of the privacy table). In some embodiments, the transformation operation is performed in response to a user request. In some embodiments, the first electronic device 302 transforms the privacy table in response to a request from a user of the first electronic device 302. In some embodiments, the first electronic device 302 transforms the privacy table based on one or more of the following: the amount of time elapsed since the privacy table 310 was generated (or received by the first electronic device 302); the number of messages encrypted / transmitted using the privacy table 310; or one or more settings (e.g., user preferences). In some embodiments, a hash algorithm defined in the transformation protocol 602 is used to transform the privacy table 310. In some embodiments, only a portion of the privacy table 310 is transformed (e.g., the portion of the privacy table 310 corresponding to the mapping 312). In some embodiments, the first electronic device 302 stores a second version 607 of the second privacy table 604 (e.g., the second version 607 indicates that the second privacy table 604 is the second version of the generated privacy table). In some embodiments, the second version 607 includes information about the type of transformation that occurred to produce the second privacy table 604. For example, the transformation protocol 602 includes parameters specified by the user when performing the transformation operation, and the second version 607 includes information about the values the user set for those parameters. In some embodiments, the second version 607 is not stored at the first electronic device 302 (excluded), and the second privacy table 604 does not have an indicator indicating its version.
[0117] In some embodiments, after transforming the privacy table 310 to create the second privacy table 604, the privacy table 310 is deleted (or marked for deletion) by the electronic device 302. In some embodiments, the privacy table 310 is retained by the first electronic device 302 (e.g., for messages received from the second electronic device 304 that were created using the privacy table 310 stored at the second electronic device 304). In some embodiments, the first electronic device 302 stores the first version of the privacy table 310 and the second version 607 of the second privacy table 604 as blocks in a blockchain ledger (e.g., the privacy table 310 as the genesis block). In some embodiments, the blockchain ledger includes version information 603 and 607. In some embodiments, the blockchain ledger is stored at the security log 112. In some embodiments, the blockchain ledger is stored at the database 240 (e.g., as blockchain information 246).
[0118] In some embodiments, the above process (e.g., operations 3 to 6) is repeated for each new message sent from the first electronic device 302 to the second electronic device 304, where a transformation operation (operation 7) occurs between at least some of the message transmissions.
[0119] The first electronic device 302 generates (operation 8) a mapping 606 (e.g., an encoding / decoding mapping) and generates a master key 608 (e.g., an encryption key) based on the mapping 606 (e.g., values in the mapping 606) and a random number (e.g., bits) stored in the privacy table 604. In some embodiments, the second mapping 606 is different from the first mapping 312 (e.g., identifying different locations in the privacy table). In some embodiments, the second mapping 606 identifies the same location as the first mapping 312, but due to the transformation of the table (in operation 7), the resulting second master key 608 is different from the first master key 316.
[0120] The first electronic device 302 encrypts (operation 9) the second message 610 (e.g., data) using the new master key 608 to form an encrypted message 612. The first electronic device 302 generates (operation 10) a new encrypted payload 614 that includes the new mapping 606 and the encrypted message 612. In some embodiments, the new encrypted payload 614 includes the mapping 606 (and, in some embodiments, a second version 607) prefixed to or appended to the encrypted message 612.
[0121] The first electronic device 302 transmits (operation 11) the new encrypted payload 614 (which includes the new mapping 606 and the encrypted message 612) to the second electronic device 304 (e.g., via an optical bar code). The new encrypted payload 614 (in operation 11) is transmitted at a time different from the time of transmitting the first encrypted payload 324 (in operation 6). In some embodiments, the first electronic device 302 waits for a response from the second electronic device 304 (e.g., an acknowledgment of the receipt of the payload 614 and / or an acknowledgment of the decryption of the payload 614). In some embodiments, if the second electronic device 304 does not respond (e.g., within a preset amount of time), the first electronic device 302 restores the second privacy table 604 to the privacy table 310 (e.g., to prevent mismatches in the case where the second electronic device 304 does not receive the payload 614 with the parameters for transforming the privacy table).
[0122] As Figure 6BAs shown, the second electronic device 304 receives (operation 12) and stores the transformed agreement 602 transmitted from the first electronic device 302 (in operation 1). The second electronic device 304 also receives (operation 13) and stores the privacy table 310 transmitted from the first electronic device 302 (in operation 2). As previously described, the transformed agreement 602 and the privacy table 310 may be sent via an encrypted channel (e.g., different from the channel used to transmit the encrypted payload).
[0123] The second electronic device 304 receives (operation 14) the first encrypted payload 324 (which includes the mapping 312, the encrypted message 322, and in some embodiments includes the first version 603) transmitted from the first electronic device 302 (in operation 6), and reads (e.g., extracts or determines) the mapping 312 from the encrypted payload 324 (operation 15a) and in some embodiments reads (e.g., extracts or determines) the first version 603 (operation 15b). In embodiments where the encrypted message includes the first version 603, the second electronic device 304 verifies (operation 16) the version of its privacy table (e.g., the privacy table 310) against the first version 603 to determine whether to transform the privacy table.
[0124] The second electronic device 304 uses the information from the mapping 312 and the privacy table 310 to recreate (operation 17) the master key 316 (e.g., generate the recreated master key 316'). In some embodiments, the second electronic device 304 generates a challenge string and uses the recreated challenge string to verify the recreated master key 316'. The second electronic device 304 uses the recreated master key 316' to decrypt (operation 18) the encrypted message 322 from the encrypted payload 324 to form the decrypted first message 326.
[0125] In some embodiments, the recreated master key 316' is the same (e.g., identical) as the master key 316. For example, in some embodiments, such as when encrypting the first message 320 using a symmetric cipher (such as AES-256), the same recreated master key 316' used to encrypt the first message 320 to form the encrypted message 322 may be used to decrypt the encrypted message 322.
[0126] At a later time point, the second electronic device 304 receives (operation 19) the encrypted payload 614 (which includes the mapping 606, the encrypted message 612, and in some embodiments includes the second version 607) transmitted from the first electronic device 302 (in operation 11), and reads (e.g., extracts or determines) the mapping 606 from the encrypted payload 614 (operation 20a) and in some embodiments reads (e.g., extracts or determines) the second version 607 (operation 20b).
[0127] In embodiments where the encrypted message includes the second version 607, the second electronic device 304 verifies (operation 21) the version of its privacy table (e.g., privacy table 310) against the second version 607 to determine whether to transform the privacy table 310. In these embodiments, the second electronic device 304 determines that the privacy table 310 is not the correct version and transforms (operation 22) the privacy table 310 using the transformation protocol 602 to generate a recreated privacy table 604'. In some embodiments, the second version 607 includes information on how to transform the privacy table 310 (e.g., includes the values of one or more parameters in the transformation protocol 602). In some embodiments, the second version 607 includes information on the number of times to transform the privacy table 310. For example, the second version 607 indicates that the encrypted payload 614 was encrypted with version 2 of the privacy table, so the privacy table 310 should be transformed once.
[0128] In embodiments where the encrypted message does not include the second version 607, the second electronic device 304 generates a master key using the privacy table 310 and verifies the generated master key. For example, the second electronic device 304 uses the information from the mapping 606 and the privacy table 310 to generate the master key. However, the master key generated from the mapping 606 and the privacy table 310 is invalid (and does not decrypt the encrypted message). In some embodiments, the second electronic device 304 determines that the master key is invalid by comparing the challenge string from the first electronic device 302 with the challenge string generated using the master key (e.g., the challenge strings do not match and thus the master key is invalid). In some embodiments, the second electronic device 304 determines that the master key is invalid based on the failure to decrypt the encrypted message. In response to determining that the master key generated from the mapping 606 and the privacy table 310 is invalid, the second electronic device 304 transforms (operation 22) the privacy table 310 using the transformation protocol 602 to generate a recreated privacy table 604'. In some embodiments, the second electronic device 304 repeats the above verification to determine whether the master key generated from the recreated privacy table 604' is valid.
[0129] The second electronic device 304 uses the information from the mapping 606 and the privacy table 604' to recreate (operation 23) the master key 608 (e.g., generate a recreated master key 608'). The second electronic device 304 uses the recreated master key 608' to decrypt (operation 24) the encrypted message 612 from the encrypted payload 614 to form a decrypted first message 626.
[0130] In some embodiments, the above process (e.g., operations 19 to 24) is repeated for each new message sent from the electronic device 302 (or other device having the shared privacy table 310) to the electronic device 304.
[0131] Figure 7AAnd Figure 7B illustrates an example of an encrypted payload according to some embodiments. In Figure 7A , the encrypted payload 702 (e.g., corresponding to the encrypted payload 324) includes an encrypted message 322, a mapping 312, and version information 706. For example, the encrypted payload 702 is a concatenation of the encrypted message 322, the mapping 312, and the version information 706. The mapping 312 was described in detail above with respect to Figure 4A . In some embodiments, as Figure 7A shown, the version information 706 includes the version number of the privacy table corresponding to the mapping 312. In some embodiments, the version information 706 is included in the mapping 312 (e.g., the mapping 312 includes a value indicating the version of the corresponding privacy table).
[0132] In Figure 7B the example of, the encrypted payload 750 includes version information 752. In some embodiments, the version information 752 includes one or more of the following: the version number of the corresponding privacy table and variant information for generating the version of the privacy table. In some embodiments, the version information 752 includes one or more of the following:
[0133] a value (e.g., a numerical value) corresponding to the version of the privacy table from which the mapping 312 was generated, represented by the letter "H";
[0134] a value (e.g., a numerical value) corresponding to the type of hash algorithm used for the variant, represented by the letter "I"; and
[0135] a value (e.g., a numerical value) corresponding to the variant part of the privacy table, represented by the letter "J".
[0136] In some embodiments, the values "I" and "J" correspond to an input of the user of the electronic device 302 (e.g., values selected by the user for the parameters in the variant agreement 602).
[0137] Figure 7CIllustrates a transformation protocol 758 according to some embodiments. In some embodiments, the transformation protocol 602 is an instance of the transformation protocol 758. The transformation protocol 758 includes a plurality of transformation algorithms 760-1 to 760-10 and one or more parameters 762. In some embodiments, the plurality of transformation algorithms 760 are selected from an algorithm pool 766. In some embodiments, the plurality of transformation algorithms 760 include one or more different types of algorithms. In some embodiments, the transformation algorithms include one or more hashing algorithms (e.g., Secure Hashing Algorithm), one or more message digest algorithms, and / or one or more ciphers. In some embodiments, the plurality of transformation algorithms 760 include one or more algorithms of the same type with different parameters. In some embodiments, the parameter 762 includes one or more parameters for transforming an associated privacy table (e.g., privacy table 310). For example, the parameter 762 includes information and / or instructions regarding the frequency of transforming the privacy table 310 (e.g., based on elapsed time or the number of messages sent).
[0138] In some embodiments, performing a transformation operation on a privacy table includes selecting a transformation algorithm from the plurality of transformation algorithms 760. In some embodiments, the transformation algorithm is selected based on user input. In some embodiments, the transformation algorithm is randomly (e.g., pseudo-randomly) selected. In some embodiments, an identifier for the selected transformation algorithm is transmitted to a remote device (e.g., from electronic device 302 to electronic device 304). In some embodiments, the identifier is transmitted to the remote device as metadata of a secure message (e.g., together with the version number of the privacy table (e.g., version 603)). In some embodiments, the identifier (and optionally the version number) of the transformation algorithm is sent separately from the secure message (e.g., in a separate communication and / or via a separate communication channel).
[0139] In some embodiments, the plurality of transformation algorithms 760 are refreshable from the algorithm pool 766. For example, after a specific number of transformations, a new set of transformation algorithms is obtained from the algorithm pool 766. As another example, a user can request a refresh of the plurality of transformation algorithms, resulting in obtaining a new set of algorithms from the algorithm pool 766.
[0140] Figures 8A to 8C A flowchart of a method 800 for secure communication (e.g., between devices of the secure communication system 100) according to some embodiments is provided. The method 800 is performed at a first electronic device (e.g., electronic device 302). The first electronic device can correspond to Figure 1 any of the electronic devices shown in (e.g., electronic device 110, 120, 130, or 140, or a device associated with the security log 112) or Figure 5 any of the devices shown in (e.g., drone 502 or landing station 508). RegardingFigure 6A and Figure 6B provides an example of secure communication between electronic devices of the secure communication system 100.
[0141] A first electronic device obtains (802) a first version of a privacy table. The privacy table includes N first bits, where N is a positive integer greater than 32. In some embodiments, the first electronic device receives the first version of the privacy table from a random number generation system (e.g., random number generation system 216). In some embodiments, the first electronic device generates (e.g., using table generation module 229) the first version of the privacy table.
[0142] The first electronic device applies (804) a predefined hash algorithm (e.g., via table transformation module 231) to the first version of the privacy table to generate a second version of the privacy table having N second bits. In some embodiments, the second version of the privacy table has more or fewer than N bits. In some embodiments, the predefined hash algorithm is (at least part of) a transformation protocol (e.g., transformation protocol 602). In some embodiments, the predefined hash algorithm (in the transformation protocol) is obtained using the first version of the privacy table (e.g., generated using the first version of the privacy table, or obtained from a random number generation system using the first version of the privacy table). In some embodiments, the predefined hash algorithm is generated based on information from a second electronic device (e.g., electronic device 304). For example, users of the first and second electronic devices can together define (agree on) the transformation protocol.
[0143] In some embodiments, the hash algorithm includes (806) one or more hash functions. In some embodiments, the hash algorithm includes two or more hash functions (e.g., one or more of them are applied each time the privacy table is transformed). In some embodiments, the hash algorithm selects which hash function to apply based on input from the user of the first electronic device (e.g., the user specifies which hash function to apply for a given transformation of the privacy table).
[0144] In some embodiments, the first electronic device sequentially hashes (808) portions of the first version of the privacy table in a predefined order to generate the second version of the privacy table. In some embodiments, the predefined order is specified in the transformation protocol. In some embodiments, the portion of the first version of the privacy table is less than the whole privacy table. For example, according to the transformation protocol, the hash algorithm is applied only to a subset of the privacy table. In some embodiments, the hash algorithm is applied only to the portion of the privacy table previously used to generate a key (e.g., the portion corresponding to mapping 312).
[0145] In some embodiments, a second version of the privacy table is generated (810) based on a preset number of messages encrypted according to a first version of the privacy table. For example, the transformation protocol of the privacy table may stipulate that each version of the privacy table is only used for 1, 5, or 10 messages. In some embodiments, a second version is generated according to a preset amount of the privacy table being used (e.g., when 25%, 50%, or 75% of the privacy table has been used for key generation).
[0146] In some embodiments, a second version of the privacy table is generated (812) in response to a request from a user of the first electronic device. For example, the user of the first electronic device may request a new version of the privacy table due to security considerations or according to a security policy for communicating with the second electronic device.
[0147] In some embodiments, the first electronic device obtains (814) a blockchain for the privacy table (e.g., from the security log 112 or the blockchain information 246). The blockchain includes a genesis block for the first version of the privacy table. According to the generation of the second version of the privacy table, the first electronic device generates (814) a second block and inserts the second block into the blockchain. In some embodiments, each version of the privacy table corresponds to a block in the blockchain.
[0148] In some embodiments, the first electronic device (i) receives (818) a second encrypted message and a version identifier of the privacy table from the second electronic device, where the version identifier indicates that the second encrypted message is generated using the first version of the privacy table. Then, the first electronic device (ii) decrypts (818) the second encrypted message using the information from the genesis block of the blockchain. For example, when the second message is based on the first version of the privacy table, the first electronic device retrieves the first version of the privacy table from the blockchain database (or generates the first version of the privacy table based on the information from the blockchain).
[0149] The first electronic device obtains (820) a first message for transmission to the second electronic device, where the second electronic device (i) has a copy of the first version of the privacy table and (ii) has access to a predefined hash algorithm. For example, the first electronic device obtains the first message from the user of the first electronic device (e.g., via the communication interface 212). In some embodiments, the first message is obtained from a message sending application running on the first electronic device. In some embodiments, the first electronic device generates the first message in response to an incoming communication or event. For example, the first electronic device generates the first message in response to a request to identify itself to a remote device.
[0150] The first electronic device generates (822) a master key based on the second version of the privacy table (e.g., using the master key generation module 232). In some embodiments, the master key is generated based on a subset (mapping) of the privacy table values.
[0151] In some embodiments, the first electronic device generates (824) a mapping based on a second version of the privacy table (e.g., via the mapping generation module 230), where (i) the mapping includes a set of parameter values specifying instructions for generating a master key from the second version of the privacy table, and (ii) the master key is generated according to the instructions in the mapping. The first electronic device then transmits (824) the mapping to the second electronic device. For example, the mapping is transmitted to the second electronic device together with an encrypted message (e.g., the mapping and the encrypted message are transmitted as an encrypted payload 324).
[0152] In some embodiments, generating a mapping based on a privacy table includes: selecting a location in the privacy table, selecting a reading direction (e.g., rotation), and generating a mapping starting from the selected location based on the values stored in the privacy table (e.g., bits or random numbers), and reading the values stored in the privacy table according to the selected reading direction. In some embodiments, the location in the privacy table (e.g., the starting location) is randomly selected. In some embodiments, the reading direction is randomly selected. In some embodiments, the location in the privacy table is selected based on a value provided by a pseudo-random number generator. In some embodiments, the reading direction is selected based on a value provided by a pseudo-random number generator. For example, the pseudo-random number generator may provide a pseudo-random number such as "-129", which corresponds to the starting location 129 in the privacy table and a negative reading direction (e.g., the reading values starting from location 129 in the privacy table and reading backward (e.g., reading from right to left)). In another example, the pseudo-random number generator may provide a pseudo-random number such as "+8", which corresponds to the starting location 8 in the privacy table and a positive reading direction (e.g., the reading values starting from location 8 in the privacy table and reading forward (e.g., reading from left to right)).
[0153] In some embodiments, generating a mapping based on a privacy table includes using a subset or a portion (less than all) of the random numbers (e.g., bits) stored in the privacy table 310 to generate the mapping. In some embodiments, the mapping does not include information (such as an identifier) about which privacy table it is associated with or from which privacy table it is generated. In some embodiments, the mapping includes random numbers from the privacy table. In some embodiments, the mapping includes a random value corresponding to a starting point within the privacy table, a value corresponding to a horizontal offset starting from the starting point within the privacy table, a value corresponding to a horizontal reading direction starting from the starting point within the privacy table, a value corresponding to a vertical offset starting from the starting point within the privacy table, a value corresponding to a vertical reading direction starting from the starting point within the privacy table, a value corresponding to the size of the privacy table in the horizontal direction (e.g., the arrangement of the size), a value corresponding to the size of the privacy table in the vertical direction (e.g., the arrangement of the size), a value corresponding to the starting point within the arrangement, and / or the length of a challenge string used to generate a master key. In some embodiments, the length of the challenge string is derived from a value corresponding to the arrangement of the size of the privacy table in the horizontal direction and a value corresponding to the arrangement of the size of the privacy table in the vertical direction.
[0154] In some embodiments, generating a master key based on the mapping and the privacy table includes generating a challenge string based on the mapping (e.g., based on the values in the mapping, based on the random numbers in the mapping), and applying a digest function to the challenge string to form the master key. In some embodiments, the master key is a digest of the challenge string, such as a SHA256 digest (e.g., as previously described with respect to Figure 3A ).
[0155] The first electronic device (e.g., via the encryption module 234) encrypts (826) the first message using the master key to form an encrypted first message (e.g., encrypted message 322). For example, to encrypt a message, the first electronic device may initialize an encryption protocol (e.g., an encryption algorithm, such as AES256), which uses the master key to encrypt the first message and form the encrypted first message.
[0156] The first electronic device transmits (828) the encrypted first message and a version identifier of a second version of the privacy table to the second electronic device (e.g., via the communication module 224). In some embodiments, the first electronic device presents the encrypted first message to the second electronic device. For example, the first electronic device presents the encrypted first message as a barcode for the second electronic device to scan. In some embodiments, the first electronic device transmits the encrypted first message via an unencrypted (unsecure) channel.
[0157] In some embodiments, the second electronic device: (i) applies (830) a predefined hashing algorithm to a first version of the privacy table to generate a second version of the privacy table (e.g.,Figure 6B operation (22) in; (ii) recreate (830) the master key from the second version of the privacy table according to the mapping (e.g., Figure 6B operation (23) in; and (iii) decrypt (830) the encrypted first message using the recreated master key (e.g., Figure 6B operation (24) in. In some embodiments, the second electronic device generates the second version of the privacy table based on information from a metamorphic protocol (e.g., metamorphic protocol 602).
[0158] In some embodiments, the first electronic device applies a predefined hash algorithm to (832) the second version of the privacy table to generate a third version of the privacy table having N third bits. In some embodiments, the first electronic device applies the predefined hash algorithm in a different manner to generate the third version compared to the second version. For example, the first electronic device applies a different hash function of the predefined hash algorithm, applies the predefined hash algorithm with different values for the parameters of the algorithm, and / or applies the algorithm to different parts of the privacy table.
[0159] In some embodiments, after transmitting the encrypted first message, the first electronic device: (i) applies (834) a predefined hash algorithm to the second version of the privacy table to generate a third version of the privacy table having N third bits; (ii) obtains (834) a second message for transmission to the second electronic device; (iii) generates (834) a second master key based on the third version of the privacy table; (iv) encrypts (834) the second message using the second master key to form an encrypted second message; and (v) transmits (834) the encrypted second message and the version identifier of the third version of the privacy table to the second electronic device.
[0160] Figure 9 A flowchart of a method 900 for secure communication (e.g., between devices of the secure communication system 100) according to some embodiments is provided. The method 900 is executed at a first electronic device (e.g., electronic device 302). The first electronic device may correspond to Figure 1 any of the electronic devices shown in (e.g., electronic devices 110, 120, 130, or 140, or a device associated with the security log 112) or Figure 5 any of the devices shown in (e.g., drone 502 or landing station 508).
[0161] The first electronic device obtains (902) a first privacy table. In some embodiments, the first privacy table is obtained from a random number generation system (e.g., random number generation system 216). In some embodiments, the first privacy table is generated (904) from a true random number generator. In some embodiments, the first privacy table is generated using a table generation module (e.g., table generation module 229). In some embodiments, the first privacy table is transmitted to the first electronic device from a random number generation system (e.g., from random number generation system 216), another electronic device, or a random number storage system.
[0162] The first electronic device transmits (906) the first privacy table to the second electronic device. In some embodiments, the first privacy table is transmitted to the second electronic device via an encrypted channel. In some embodiments, an encrypted version of the first privacy table is transmitted (908) to the second electronic device. In some embodiments, the first privacy table is encrypted using an encryption module (e.g., encryption module 234).
[0163] The first electronic device obtains (910) a second privacy table. In some embodiments, the second privacy table is obtained from a random number generation system (e.g., random number generation system 216). In some embodiments, the second privacy table is generated (912) from the first privacy table. For example, the second privacy table is a transformation of the first privacy table (e.g., generated using table transformation module 231).
[0164] The first electronic device encrypts (914) the second privacy table using the first privacy table. In some embodiments, the first electronic device generates a key from the first privacy table (e.g., using the master key generation module 232). In some embodiments, the first electronic device uses the key generated from the first privacy table to encrypt the second privacy table. In some embodiments, the second privacy table is encrypted using an encryption module (e.g., encryption module 234).
[0165] The first electronic device transmits (916) the encrypted second privacy table to the second electronic device. In some embodiments, the second privacy table is transmitted to the second electronic device via an encrypted channel.
[0166] The first electronic device receives (918) a digest of the second privacy table from the second electronic device. For example, the second electronic device generates a digest in response to receiving / decrypting the second privacy table.
[0167] In some embodiments, the second electronic device decrypts the second privacy table using a decryption module (e.g., decryption module 236). In some embodiments, the second electronic device uses a mapping of the first privacy table (e.g., a mapping received from the first electronic device) to decrypt the second privacy table. In some embodiments, after decrypting the second privacy table, the second electronic device generates a digest of the second privacy table and transmits the digest to the first electronic device.
[0168] The first electronic device confirms (920) the second privacy table based on the received digest. In some embodiments, the first electronic device confirms that the digest received from the second electronic device matches the digest generated by the first electronic device (e.g., generated from the second privacy table). In some embodiments, confirming the second privacy table includes approving the use of the second privacy table to encrypt future communications with the second electronic device. In some embodiments, confirming the second privacy table includes replacing the first privacy table with the second privacy table. In some embodiments, confirming the second privacy table includes using the second privacy table for future encryption associated with the second electronic device (e.g., future encrypted messages between the first electronic device and the second electronic device). In some embodiments, based on the confirmation of the second privacy table, the first electronic device sends a confirmation to the second electronic device (e.g., notifying the second electronic device that the second privacy table can be used).
[0169] Now turning to some example embodiments of the methods, devices, systems, and computer-readable storage media described above.
[0170] (A1) In one aspect, some embodiments include a method of protecting communications between electronic devices (e.g., method 800). In some embodiments, the method is performed at a first electronic device (e.g., computer system 200) having a memory 220 and one or more processors 210. The method includes: (i) obtaining (e.g., from a random number generation system 216) a first version of a privacy table that includes N first bits, where N is a positive integer greater than 32; (ii) applying (e.g., via a table transformation module 231) a predefined hash algorithm to the first version of the privacy table to generate a second version of the privacy table having N second bits; (iii) obtaining (e.g., via a communication module 224 and / or a communication interface 212) a first message for transmission to a second electronic device that (a) has a copy of the first version of the privacy table and (b) has access to the predefined hash algorithm; (iv) generating (e.g., via a master key generation module 232) a master key based on the second version of the privacy table; (v) encrypting (e.g., via an encryption module 236) the first message using the master key to form an encrypted first message; and (vi) transmitting (e.g., via a communication module 224) the encrypted first message and a version identifier of the second version of the privacy table to the second electronic device. In some embodiments, N is greater than or equal to 128.
[0171] (A2) In some embodiments of A1: (a) generating the master key includes: (i) generating (e.g., via a mapping generation module 230) a mapping based on the second version of the privacy table, where the mapping includes a specification for generating the master key from the second version of the privacy table (e.g., as previously described with respect to Figure 4Aa set of parameter values of the instructions (described); and (ii) generating a master key according to the instructions in the mapping; and (b) the method further includes transmitting the mapping to a second electronic device (e.g., via the communication module 224). In some embodiments, the mapping and the encrypted first message are transmitted to the second electronic device.
[0172] (A3) In some embodiments of A2, the second electronic device decrypts the first message by: (i) applying a predefined hash algorithm (e.g., via the table transformation module 231) to the first version of the privacy table to generate a second version of the privacy table; (ii) recreating the master key from the second version of the privacy table according to the mapping (e.g., via the master key generation module 232); and (iii) decrypting the encrypted first message using the recreated master key (e.g., via the decryption module 236).
[0173] (A4) In some embodiments of any one of A1 - A3, the hash algorithm includes applying one or more hash functions (e.g., SHA or MD5 algorithm). In some embodiments, the hash algorithm is at least a part of a transformation protocol (e.g., transformation protocol 602). In some embodiments, the hash algorithm has one or more parameters that can be set by the user of the first electronic device.
[0174] (A5) In some embodiments of any one of A1 - A4, the method further includes applying a predefined hash algorithm to the second version of the privacy table to generate a third version of the privacy table having N third bits (e.g., via the table transformation module 231). In some embodiments, different hash functions are used for the second version and the third version. In some embodiments, the third version of the privacy table is added to the blockchain ledger as a new block.
[0175] (A6) In some embodiments of any one of A1 - A5, applying a predefined hash algorithm to the first version of the privacy table includes sequentially hashing parts of the first version of the privacy table in a predefined order. For example, starting from a first position (e.g., start, middle, or end) and sequentially browsing through the various fields or parts of the privacy table.
[0176] (A7) In some embodiments of any one of A1 - A6: (i) the predefined hash algorithm includes one or more numerical parameters; and (ii) applying the predefined hash algorithm includes generating and using corresponding parameter values for each of the one or more numerical parameters; and (iii) the method further includes transmitting the parameter values together with the version identifier of the second version of the privacy table to the second electronic device (e.g., as previously described with respect to Figure 7B described).
[0177] (A8)In some embodiments of any one of A1 - A7, the method further includes transmitting a first version of the privacy table to a second electronic device via an encrypted channel. In some embodiments, the privacy table is transmitted on a channel different from the encrypted message.
[0178] (A9)In some embodiments of any one of A1 - A8, a second version of the privacy table is generated based on a preset amount of time elapsed after creating the first version of the privacy table. For example, the variant protocol of the privacy table specifies that a new version of the privacy table should be generated weekly, monthly, or annually.
[0179] (A10)In some embodiments of any one of A1 - A9, a second version of the privacy table is generated based on a preset number of messages encrypted using the first version of the privacy table. For example, the variant protocol of the privacy table specifies that a new version of the privacy table should be generated after transmitting (or receiving) 1, 5, or 10 messages. In some embodiments, the second version of the privacy table is generated based on both the amount of time elapsed after creating the first version and the number of encrypted messages.
[0180] (A11)In some embodiments of any one of A1 - A10, a second version of the privacy table is generated in response to a request from a user of the first electronic device. For example, a user interface (e.g., for a corresponding message - sending application) with a functionality affordance for generating a new version of the privacy table is presented to the user of the first electronic device.
[0181] (A12)In some embodiments of any one of A1 - A11, the method further includes, after transmitting the first encrypted message: (i) applying a predefined hash algorithm to the second version of the privacy table to generate a third version of the privacy table having N least - significant bits; (ii) obtaining a second message for transmission to the second electronic device; (iii) generating a second master key based on the third version of the privacy table; (iv) encrypting the second message using the second master key to form an encrypted second message; and (v) transmitting the encrypted second message and a version identifier of the third version of the privacy table to the second electronic device (e.g., as described in operations 7 - 11 with respect to Figure 6A ).
[0182] (A13)In some embodiments of any one of A1 - A12, the method further includes: (i) obtaining a blockchain for the privacy table (e.g., from a security log 112), the blockchain including a genesis block for the first version of the privacy table; and (ii) generating a second block and inserting the second block into the blockchain according to the generation of the second version of the privacy table.
[0183] (A14)In some embodiments of A13, the method further includes: (i) after generating a second version of the privacy table, receiving, from a second electronic device, a second encrypted message and a version identifier of the privacy table, the version identifier indicating that the second encrypted message is generated using a first version of the privacy table; and (ii) decrypting the second encrypted message using information from the genesis block of the blockchain. For example, to obtain a previous version of the privacy table, the first electronic device retrieves the previous version (or information for reconstructing the previous version) from the blockchain.
[0184] (B1)In another aspect, some embodiments include a method (e.g., method 900) for protecting communication between electronic devices. In some embodiments, the method is executed at a first electronic device (e.g., computer system 200) having a memory 220 and one or more processors 210. The method includes: (i) obtaining a first privacy table; (ii) transmitting the first privacy table to a second electronic device; (iii) obtaining a second privacy table; (iv) encrypting the second privacy table using information from the first privacy table; and (v) transmitting the encrypted second privacy table to the second electronic device. In some embodiments, the second privacy table is obtained from a random number generation system (e.g., random number generation system 216).
[0185] (B2)In some embodiments of B1, the second privacy table is generated at the first electronic device. In some embodiments, the second privacy table is generated by transforming the first privacy table stored at the first electronic device.
[0186] (B3)In some embodiments of B1 or B2, the method further includes receiving and decrypting the encrypted second privacy table at the second electronic device.
[0187] (B4)In some embodiments of B3, the method further includes generating a summary of the second privacy table at the second electronic device and transmitting the summary to the first electronic device.
[0188] (B5)In some embodiments of B4, the method further includes receiving the summary at the first electronic device and using the summary to confirm the decryption of the second privacy table at the second electronic device. In some embodiments, the first electronic device compares the received summary with a summary generated from the second privacy table stored at the first electronic device.
[0189] (B6)In some embodiments of any of B1 - B5, the second privacy table is encrypted using a key generated from the first privacy table.
[0190] (B7)In some embodiments of any of B1 - B6, the first electronic device transmits a mapping to the second electronic device to assist the second electronic device in decrypting the encrypted second privacy table.
[0191] In another aspect, some embodiments include a computing system that includes one or more processors and a memory coupled to the one or more processors, the memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for performing any of the methods described herein (e.g., the methods 800, 900, A1 - A14, and / or B1 - B7 above).
[0192] In yet another aspect, some embodiments include a non - transitory computer - readable storage medium storing one or more programs configured for execution by one or more processors of a computing system, the one or more programs including instructions for performing any of the methods described herein (e.g., the methods 800, 900, A1 - A14, and / or B1 - B7 above).
[0193] The terms used in the description of the various embodiments described herein are for the purpose of describing particular embodiments only and are not intended to be limiting. As used in the description of the various embodiments and the appended claims, unless the context clearly dictates otherwise, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well. It is also to be understood that the term “and / or” as used herein refers to any and all possible combinations of one or more of the associated listed items and includes those combinations. It should also be understood that when used in this specification, the terms “includes,” “including,” “comprises,” and / or “comprising” specify the presence of the stated features, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, steps, operations, elements, components, and / or combinations thereof.
[0194] As used herein, the term “if” means “when” or “upon” or “in response to determining” or “in response to detecting” or “in accordance with a determination,” depending on the context. Similarly, the phrase “if determined” or “if detected
stated condition or event
stated condition or event
stated condition or event
stated condition or event
[0195] It should also be understood that although the terms first and second are used in some instances herein to describe various elements, these elements should not be limited by these terms. These terms are only used to distinguish one element from another.
[0196] Although some of the various figures illustrate multiple logical stages in a particular order, stages that are not order-dependent can be reordered and other stages can be combined or broken apart. While some reorderings or other groupings are specifically mentioned, other orderings or groupings will be apparent to those of ordinary skill in the art, so the orderings and groupings presented herein are not an exhaustive list of alternatives. Additionally, it should be recognized that these stages can be implemented in hardware, firmware, software, or any combination thereof.
[0197] For purposes of illustration, the foregoing description has been described with reference to specific embodiments. However, the above illustrative discussion is not intended to be exhaustive or to limit the scope to the precise forms disclosed. Given the above teachings, many modifications and variations are possible. The embodiments were chosen and described in order to best illustrate the main principles and the practical application, so as to enable others skilled in the art to best utilize the various embodiments and various modifications suited to the particular use contemplated.
Claims
1. A method performed at a first electronic device, comprising: Obtaining a first version of a privacy table, the privacy table including N first bits, where N is a positive integer greater than 32; Applying a predefined hash algorithm to the first version of the privacy table to generate a second version of the privacy table having N second bits; Obtaining a first message for transmission to a second electronic device, the second electronic device (i) having a copy of the first version of the privacy table and (ii) having access to the predefined hash algorithm; Generating a master key based on the second version of the privacy table; Encrypting the first message using the master key to form an encrypted first message; And Transmitting the encrypted first message and a version identifier for the second version of the privacy table to the second electronic device.
2. The method according to claim 1, wherein Generating the master key includes: Generating a mapping based on the second version of the privacy table, where the mapping includes a set of parameter values specifying instructions for generating the master key from the second version of the privacy table; and Generating the master key according to the instructions in the mapping; and The method further includes transmitting the mapping to the second electronic device.
3. The method according to claim 2, wherein The second electronic device decrypts the first message by: Applying the predefined hash algorithm to the first version of the privacy table to generate the second version of the privacy table; Recreating the master key from the second version of the privacy table according to the mapping; And Decrypting the encrypted first message using the recreated master key.
4. The method according to claim 1, wherein Applying the predefined hash algorithm includes applying one or more hash functions.
5. The method according to claim 1, further comprising applying the predefined hash algorithm to the second version of the privacy table to generate a third version of the privacy table having N third bits.
6. The method according to claim 1, wherein, Applying the predefined hash algorithm to the first version of the privacy table includes sequentially hashing portions of the first version of the privacy table in a predefined order.
7. The method according to claim 1, wherein: The predefined hash algorithm includes one or more numerical parameters; and Applying the predefined hash algorithm includes generating and using corresponding parameter values for each of the one or more numerical parameters; and The method further includes transmitting the parameter values together with the version identifier of the second version of the privacy table to the second electronic device.
8. The method according to claim 1, further comprising transmitting the first version of the privacy table to the second electronic device via an encrypted channel.
9. The method according to claim 1, wherein Generating the second version of the privacy table according to a preset amount of time elapsed after creating the first version of the privacy table.
10. The method according to claim 1, wherein, Generating the second version of the privacy table according to a preset number of messages encrypted using the first version of the privacy table.
11. The method according to claim 1, wherein, Generating the second version of the privacy table in response to a request from a user of the first electronic device.
12. The method according to claim 1, further comprising, after transmitting the encrypted first message: Apply the predefined hash algorithm to the second version of the privacy table to generate a third version of the privacy table having N third bits; Obtain a second message for transmission to the second electronic device; Generate a second master key based on the third version of the privacy table; Encrypt the second message using the second master key to form an encrypted second message; and Transmit the encrypted second message and a version identifier for the third version of the privacy table to the second electronic device.
13. The method according to claim 1, further comprising: Obtain a blockchain for the privacy table, the blockchain including a genesis block for the first version of the privacy table; and Generate a second block according to generating the second version of the privacy table and insert the second block into the blockchain.
14. The method according to claim 13, further comprising: After generating the second version of the privacy table, receive a second encrypted message and a version identifier for the privacy table from the second electronic device, the version identifier indicating that the second encrypted message is generated using the first version of the privacy table; and Decrypt the second encrypted message using information from the genesis block of the blockchain.
15. A computing device, comprising: One or more processors; And A memory coupled to the one or more processors, the memory storing one or more programs configured to be executed by the one or more processors, the one or more programs including instructions for performing the following operations: Obtain a first version of a privacy table, the privacy table including N first bits, where N is a positive integer greater than 32; Apply a predefined hash algorithm to the first version of the privacy table to generate a second version of the privacy table having N second bits; Obtain a first message for transmission to a second electronic device, the second electronic device (i) having a copy of the first version of the privacy table and (ii) having access to the predefined hash algorithm; Generate a master key based on the second version of the privacy table; Encrypt the first message using the master key to form an encrypted first message; and Transmit the encrypted first message and a version identifier for the second version of the privacy table to the second electronic device.
16. The computing device according to claim 15, wherein, The instructions for generating the master key include instructions for the following operations: Generate a mapping based on the second version of the privacy table, where the mapping includes a set of parameter values specifying instructions for generating the master key from the second version of the privacy table; and Generate the master key according to the instructions in the mapping; and The one or more programs further include instructions for transmitting the mapping to the second electronic device.
17. The computing device according to claim 15, wherein, The instructions for applying the predefined hash algorithm to the first version of the privacy table include instructions for sequentially hashing portions of the first version of the privacy table in a predefined order.
18. The computer device according to claim 15, wherein Generate the second version of the privacy table according to a preset amount of time elapsed after creating the first version of the privacy table.
19. The computing device according to claim 15, wherein, The one or more programs further include instructions for performing the following operations: Obtain a blockchain for the privacy table, the blockchain including a genesis block for the first version of the privacy table; and Generate a second block and insert the second block into the blockchain according to the generation of the second version of the privacy table.
20. A non-transitory computer-readable storage medium storing one or more programs configured to be executed by a computer system having one or more processors and a memory, the one or more programs including instructions for: Obtain a first version of a privacy table, the privacy table including N first bits, where N is a positive integer greater than 32; Apply a predefined hash algorithm to the first version of the privacy table to generate a second version of the privacy table having N second bits; Obtain a first message for transmission to a second electronic device that (i) has a copy of the first version of the privacy table and (ii) has access to the predefined hash algorithm; Generate a master key based on the second version of the privacy table; Encrypt the first message using the master key to form an encrypted first message; and Transmit the encrypted first message and a version identifier for the second version of the privacy table to the second electronic device.
Citation Information
Patent Citations
Electromechanical apparatus, system, and method for generating true random numbers
US11474790B2
System and method for secure end-to-end electronic communication using a privately shared table of entropy
US11621841B2
System and method for secure end-to-end electronic communication using a privately shared table of entropy
US20220337407A1